CVE-2020-25010: Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Firmware

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a file.

Affected products

  • Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Firmware: version r0002.p05 only

Published 2020-12-17. Last modified 2026-06-17.